Fortinet FortiNAC-F
cpe:2.3:a:fortinet:fortinac-f:*:*:*:*:*:*:*
- >= 7.6.0, <= 7.6.5
- ~7.4
- ~7.2
A vulnerability allowing URL redirection to untrusted sites (open redirect) has been identified in Fortinet FortiNAC-F versions 7.6.0 through 7.6.5, as well as all versions of FortiNAC-F 7.4 and 7.2. This vulnerability may enable a remote privileged attacker with system administrator rights to redirect users to arbitrary websites by using a specially crafted CSV file.
Exploitation of this vulnerability could lead to unauthorized redirection of users to malicious websites, potentially causing phishing or other types of attacks.
Users of Fortinet FortiNAC-F 7.6 should upgrade to version 7.6.6 or above. Those on FortiNAC-F 7.4 or 7.2 should migrate to a fixed release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.